Release date: 2012-12-06 update date: 2012-12-08 affected system: RedHatCertificateSystem8RedHatCertificateSystem Description: describugtraqid: 56843CVE
Release date: 2012-6 6
Updated on: 2012-12-08
Affected Systems:
RedHat Certificate System 8
RedHat Certificate System
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56843
CVE (CAN) ID: CVE-2012-4555
Red Hat Certificate System is a software System that manages enterprise-level PKI deployment.
The Red Hat Certificate System (RHCS) token processing System has a denial of service vulnerability in interrupting the token formatting operation. A local attacker suddenly interrupts the token formatting operation, this vulnerability can cause the pki-tps NULL pointer reference vulnerability, which causes the apache http Server to restart, and other users who log on to the server are temporarily unable to use the service.
<* Source: Red Hat
Link: https://access.redhat.com/security/cve/CVE-2012-4555
Https://bugzilla.redhat.com/show_bug.cgi? CVE-2012-4555
Https://www.redhat.com/support/errata/RHSA-2012-1550.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RedHat
------
For this reason, RedHat has released a Security Bulletin (RHSA-2012: 1550-01) and patch:
RHSA-2012: 1550-01: Moderate: pki security update
Link: https://www.redhat.com/support/errata/RHSA-2012-1550.html